CVE-2010-5298
published 2014-04-14CVE-2010-5298: Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to…
PriorityP429medium4CVSS 2.0
AVNACHAuNCNIPAP
EPSS
34.13%
98.2th percentile
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products | — | — |
| debian | openssl | < openssl 1.0.1g-3 (bookworm) | openssl 1.0.1g-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mariadb | mariadb | >= 10.0.0 < 10.0.13 | 10.0.13 |
| openssl | openssl | <= 1.0.1g | — |
| openssl | openssl | >= 0 < 1.0.1g-3 | 1.0.1g-3 |
| openssl | openssl | >= 0 < 1.0.1g-3 | 1.0.1g-3 |
| openssl | openssl | >= 0 < 1.0.1g-3 | 1.0.1g-3 |
| openssl | openssl | >= 0 < 1.0.1g-3 | 1.0.1g-3 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.1 | 1.0.1f-1ubuntu2.1 |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
osv4.0MEDIUM
vendor_cisco10.0CRITICAL
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
CISA ICS
Siemens OpenSSL Vulnerabilities (Update G)
cisa_ics·2014-10-16
Siemens OpenSSL Vulnerabilities (Update G)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens OpenSSL Vulnerabilities (Update G)
Last RevisedAugust 29, 2018
Alert CodeICSA-14-198-03G
## OVERVIEW
This updated advisory is a follow-up to the updated advisory titled ICSA-14-198-03F Siemens OpenSSL Vulnerabilities that was published October 16, 2014, on the NCCIC/ICS-CERT web site.
## --------- Begin Update G Part 1 of 3 --------
Siemens has identified four vulnerabilities in its OpenSSL cryptographic software library affecting several Siemens industrial products. Updates are available for APE 2.0.2, S7-1500, WinCC OA (PVSS), CP1543-1, Ruggedcom ROX 1, and ROX 2-bas
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
vendor_cisco·2014-06-05·CVSS 10.0
CVE-2010-5298 [CRITICAL] Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code, create a denial of service (DoS) condition, or perform a man-in-the-middle attack. On June 5, 2014, the OpenSSL Project released a security advisory detailing seven distinct vulnerabilities. The vulnerabilities are referenced in this document as follows:
SSL/TLS Man-in-the-Middle Vulnerability
DTLS Recursion Flaw Vulnerability
DTLS Invalid Fragment Vulnerability
SSL_MODE_RELEASE_BUFFERS NULL Pointer Dereference Vulnerability
SSL_MODE_RELEASE_BUFFERS Session Injection or Denial of Service Vulnerability
Anonymous ECDH Denial of Service Vulnerab
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2014-05-05·CVSS 4.0
CVE-2010-5298 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL could be made to crash if it received specially crafted network
traffic.
It was discovered that OpenSSL incorrectly handled memory in the
ssl3_read_bytes() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2010-5298)
It was discovered that OpenSSL incorrectly handled memory in the
do_ssl3_write() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2014-0198)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
BSD
FreeBSD-SA-14:09.openssl: OpenSSL use-after-free vulnerability
bsd_advisories·2014-04-30·CVSS 4.0
CVE-2010-5298 [MEDIUM] FreeBSD-SA-14:09.openssl: OpenSSL use-after-free vulnerability
FreeBSD-SA-14:09.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL use-after-free vulnerability
Category: contrib
Module: openssl
Announced: 2014-04-30
Affects: FreeBSD 10.x.
Corrected: 2014-04-30 04:03:05 UTC (stable/10, 10.0-STABLE)
2014-04-30 04:04:42 UTC (releng/10.0, 10.0-RELEASE-p2)
CVE Name: CVE-2010-5298
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
0. Revision History
v1.0 2014-04-30 Initial release.
v1.1 2014-04-30 Added patch applying step in Solutions section.
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is
a collaborative effort to develop a robust, commercial-grade, full-featured
Open Source toolk
Red Hat
openssl: freelist misuse causing a possible use-after-free
vendor_redhat·2014-04-08·CVSS 4.0
CVE-2010-5298 [MEDIUM] CWE-416 openssl: freelist misuse causing a possible use-after-free
openssl: freelist misuse causing a possible use-after-free
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
Statement: This issue did not affect the openssl packages shipped with Red Hat Enterprise Linux 5.
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a (Red Hat Enterprise Linux 5) - Not affected
Package: guest-images (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 7) - Not affected
Package: mi
Debian
CVE-2010-5298: openssl - Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1....
vendor_debian·2010·CVSS 4.0
CVE-2010-5298 [MEDIUM] CVE-2010-5298: openssl - Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1....
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
Scope: local
bookworm: resolved (fixed in 1.0.1g-3)
bullseye: resolved (fixed in 1.0.1g-3)
forky: resolved (fixed in 1.0.1g-3)
sid: resolved (fixed in 1.0.1g-3)
trixie: resolved (fixed in 1.0.1g-3)
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
vendor_cisco
CVE-2010-5298 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
CVE-2010-5298: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code, create a denial of service (DoS) condition, or perform a man-in-the-middle attack. On June 5, 2014, the OpenSSL Project released a security advisory detailing seven distinct vulnerabilities. The vulnerabilities are referenced in this document as follows: SSL/TLS Man-in-the-Middle Vulnerability DTLS Recursion Flaw Vulnerability DTLS Invalid Fragment Vulnerability SSL_MODE_RELEASE_BUFFERS NULL Pointer Dereference Vulnerability SSL_MODE_RELEASE_BUFFERS Session Injection or Denial of Service Vulnerability Anonymous ECDH Denial of Ser
GHSA
GHSA-m249-hh62-97m2: Race condition in the ssl3_read_bytes function in s3_pkt
ghsa_unreviewed·2022-05-14
CVE-2010-5298 [MEDIUM] CWE-362 GHSA-m249-hh62-97m2: Race condition in the ssl3_read_bytes function in s3_pkt
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
OSV
openssl vulnerabilities
osv·2014-05-05·CVSS 4.0
CVE-2010-5298 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
It was discovered that OpenSSL incorrectly handled memory in the
ssl3_read_bytes() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2010-5298)
It was discovered that OpenSSL incorrectly handled memory in the
do_ssl3_write() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2014-0198)
OSV
CVE-2010-5298: Race condition in the ssl3_read_bytes function in s3_pkt
osv·2014-04-14·CVSS 4.0
CVE-2010-5298 [MEDIUM] CVE-2010-5298: Race condition in the ssl3_read_bytes function in s3_pkt
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]
bugzilla·2014-08-07·CVSS 4.0
CVE-2014-0221 [MEDIUM] CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]
The unfixed package from Fedora was added to EPEL-7.
+++ This bug was initially created as a clone of Bug #1096234 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relev
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]
bugzilla·2014-05-09·CVSS 4.0
CVE-2014-0221 [MEDIUM] CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avai
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]
bugzilla·2014-05-09·CVSS 4.0
CVE-2014-0221 [MEDIUM] CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field whe
Bugzilla
CVE-2010-5298 openssl: freelist misuse causing a possible use-after-free
bugzilla·2014-04-14·CVSS 4.0
CVE-2010-5298 [MEDIUM] CVE-2010-5298 openssl: freelist misuse causing a possible use-after-free
CVE-2010-5298 openssl: freelist misuse causing a possible use-after-free
The following security advisory was reported by OpenBSD:
OpenBSD 5.4 errata 8, Apr 12, 2014: A use-after-free race condition in OpenSSL's read buffer may permit an attacker to inject data from one connection into another.
Reference:
http://ftp.openbsd.org/pub/OpenBSD/patches/5.4/common/008_openssl.patch
http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse
Discussion:
Analysis:
openssl does its own memory management and maintains a LIFO freelist of buffers available.
In ssl3_read_bytes(), it released buffer even if there is some data available inside it.
Later in s3_pkt.c:1058, ssl3_release_read_buffer() is called to allocate another buffer. In a single threaded application the same buffer wo
Tenable
OpenSSL ChangeCipherSpec Dashboard
blogs_tenable·2014-06-06
OpenSSL ChangeCipherSpec Dashboard
by Steve Tilson June 6, 2014
The OpenSSL ChangeCipherSpec vulnerability is a Man-in-the-Middle attack that can allow an attacker modify the traffic between two hosts during a phase of an SSL/TLS handshake. This flaw could allow a MiTM attacker to decrypt or forge SSL messages by telling the service to begin encrypted communications before key material has been exchanged, which causes predictable keys to be used to secure future traffic. This dashboard identifies systems vulnerable to the OpenSSL ChangeCipherSpec vulnerability.
Man-in-the-Middle (MitM) vulnerabilities allow an attacker to insert themselves into a communication channel. While each of the endpoints assume they are communicating directly with each other, all the traffic is in fact flowing through the attacker. This type of h
http://advisories.mageia.org/MGASA-2014-0187.htmlhttp://ftp.openbsd.org/pub/OpenBSD/patches/5.5/common/004_openssl.patch.sighttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlhttp://marc.info/?l=bugtraq&m=140389274407904&w=2http://marc.info/?l=bugtraq&m=140389355508263&w=2http://marc.info/?l=bugtraq&m=140431828824371&w=2http://marc.info/?l=bugtraq&m=140448122410568&w=2http://marc.info/?l=bugtraq&m=140544599631400&w=2http://marc.info/?l=bugtraq&m=140621259019789&w=2http://marc.info/?l=bugtraq&m=140752315422991&w=2http://marc.info/?l=bugtraq&m=140904544427729&w=2http://marc.info/?l=bugtraq&m=141658880509699&w=2http://openwall.com/lists/oss-security/2014/04/13/1http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/58337http://secunia.com/advisories/58713http://secunia.com/advisories/58939http://secunia.com/advisories/58977http://secunia.com/advisories/59162http://secunia.com/advisories/59287http://secunia.com/advisories/59300http://secunia.com/advisories/59301http://secunia.com/advisories/59342http://secunia.com/advisories/59413http://secunia.com/advisories/59437http://secunia.com/advisories/59438http://secunia.com/advisories/59440http://secunia.com/advisories/59450http://secunia.com/advisories/59490http://secunia.com/advisories/59655http://secunia.com/advisories/59666http://secunia.com/advisories/59669http://secunia.com/advisories/59721http://security.gentoo.org/glsa/glsa-201407-05.xmlhttp://support.citrix.com/article/CTX140876http://svnweb.freebsd.org/ports/head/security/openssl/files/patch-ssl-s3_pkt.c?revision=351191&view=markuphttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-opensslhttp://www-01.ibm.com/support/docview.wss?uid=swg21673137http://www-01.ibm.com/support/docview.wss?uid=swg21676035http://www-01.ibm.com/support/docview.wss?uid=swg21676062http://www-01.ibm.com/support/docview.wss?uid=swg21676419http://www-01.ibm.com/support/docview.wss?uid=swg21676529http://www-01.ibm.com/support/docview.wss?uid=swg21676655http://www-01.ibm.com/support/docview.wss?uid=swg21676879http://www-01.ibm.com/support/docview.wss?uid=swg21676889http://www-01.ibm.com/support/docview.wss?uid=swg21677527http://www-01.ibm.com/support/docview.wss?uid=swg21677695http://www-01.ibm.com/support/docview.wss?uid=swg21677828http://www-01.ibm.com/support/docview.wss?uid=swg21677836http://www-01.ibm.com/support/docview.wss?uid=swg21678167http://www-01.ibm.com/support/docview.wss?uid=swg21683332http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757http://www.blackberry.com/btsc/KB36051http://www.fortiguard.com/advisory/FG-IR-14-018/http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htmhttp://www.ibm.com/support/docview.wss?uid=swg21676356http://www.ibm.com/support/docview.wss?uid=swg24037783http://www.mandriva.com/security/advisories?name=MDVSA-2014:090http://www.mandriva.com/security/advisories?name=MDVSA-2015:062http://www.openbsd.org/errata55.html#004_opensslhttp://www.openssl.org/news/secadv_20140605.txthttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/66801http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reusehttp://www.vmware.com/security/advisories/VMSA-2014-0006.htmlhttp://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946https://kb.bluecoat.com/index?page=content&id=SA80https://kc.mcafee.com/corporate/index?page=content&id=SB10075https://rt.openssl.org/Ticket/Display.html?id=2167&user=guest&pass=guesthttps://rt.openssl.org/Ticket/Display.html?id=3265&user=guest&pass=guesthttps://www.novell.com/support/kb/doc.php?id=7015271http://advisories.mageia.org/MGASA-2014-0187.htmlhttp://ftp.openbsd.org/pub/OpenBSD/patches/5.5/common/004_openssl.patch.sighttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlhttp://marc.info/?l=bugtraq&m=140389274407904&w=2http://marc.info/?l=bugtraq&m=140389355508263&w=2http://marc.info/?l=bugtraq&m=140431828824371&w=2http://marc.info/?l=bugtraq&m=140448122410568&w=2http://marc.info/?l=bugtraq&m=140544599631400&w=2http://marc.info/?l=bugtraq&m=140621259019789&w=2http://marc.info/?l=bugtraq&m=140752315422991&w=2http://marc.info/?l=bugtraq&m=140904544427729&w=2http://marc.info/?l=bugtraq&m=141658880509699&w=2http://openwall.com/lists/oss-security/2014/04/13/1http://seclists.org/fulldisclosure/2014/Dec/23
+ 64 more references
2014-04-14
Published